cbcvebase.
CVE-2013-1976
published 2013-07-09

CVE-2013-1976: The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red…

medium6.9CVSS 3.1
AVLACMAuNCCICAC
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.

Affected

4 ranges
VendorProductVersion rangeFixed in
redhatenterprise_linux
redhatenterprise_linux
redhatjboss_enterprise_web_server
redhatjboss_enterprise_web_server